QuestionQ22

Threat Hunting Techniques

Refer to the exhibit.

Question Image

Code analysis is performed using the Semgrep tool. The tool reports that a security issue occurred while connecting to the database.

Which security vulnerability does the tool flag?

Explanation

Concatenating accountName directly into a SQL string passed to executeQuery allows untrusted input to alter the SQL statement. This is SQL injection; parameterized statements bind input separately from the SQL command.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!